#ai-identity
- Analysis · Aug 29, 2026Agent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The delegation standard is arriving faster than the governance around it.
- News · Aug 24, 2026Okta ships Agent SSO, making AI agents first-class identities instead of static API keys
Okta made Agent SSO generally available on August 24, 2026, registering AI agents in Universal Directory with short-lived governed tokens and pushing Cross App Access into the Model Context Protocol as its enterprise authorization extension.
- News · Aug 7, 2026Opening a GitHub issue was enough to reach CI secrets in Claude Code and Gemini CLI
Novee Security showed at Black Hat that an unprivileged GitHub user could open an issue that reached workflow credentials on the coding-agent repositories of Anthropic, Google, and OpenAI. Fixes shipped in Gemini CLI 0.39.1 and Claude Code 2.1.163.
- News · Aug 5, 2026A CVSS 10.0 bug let one user's Terraform token serve another user's request
HashiCorp's Terraform MCP Server failed to assign unique session identifiers in stateless HTTP mode, so a token supplied by one user could be reused for later requests from others. Veeam and Django patched serious flaws the same week.
- Analysis · Jun 4, 2026Agentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was designed for them.